CVE-2016-1288
published 2016-03-03CVE-2016-1288: The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a…
PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
1.74%
75.2th percentile
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance_https_packet_processing | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq33-86v9-3777: The HTTPS Proxy feature in Cisco AsyncOS before 8
ghsa_unreviewed·2022-05-14
CVE-2016-1288 [MEDIUM] CWE-20 GHSA-rq33-86v9-3777: The HTTPS Proxy feature in Cisco AsyncOS before 8
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
Cisco
Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
vendor_cisco·2016-03-02·CVSS 7.8
CVE-2016-1288 [HIGH] CWE-399 Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
A vulnerability in the web proxy framework of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker with the ability to negotiate a secure connection from within the trusted network to cause a denial of service (DoS) condition on the affected device.
The vulnerability is due to incorrect processing of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS request packet through the affected device. A successful exploit could allow an attacker to create a DoS condition, causing all requests traversing the WSA to be dropped. The condition is temporary and no manual intervention is required to restore functionality.
Cisco has released softwa
Cisco
Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
vendor_cisco
CVE-2016-1288 Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
CVE-2016-1288: Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability
A vulnerability in the web proxy framework of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker with the ability to negotiate a secure connection from within the trusted network to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to incorrect processing of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS request packet through the affected device. A successful exploit could allow an attacker to create a DoS condition, causing all requests traversing the WSA to be dropped. The condition is temporary and no manual intervention is required to restore functionality. Cisco has re
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-03-03
Published